Midnight Mimosa là chiến dịch mã độc chuỗi cung ứng được Bitdefender công bố ngày 8/10/2026, nhắm vào các điện thoại Android giá rẻ sử dụng nền tảng MediaTek. Thành phần độc hại được cài sẵn trong firmware, chạy với đặc quyền hệ thống và có thể âm thầm cài ứng dụng, gian lận quảng cáo hoặc biến điện thoại thành nút proxy dân cư trước khi chủ sở hữu có cơ hội tự bảo vệ.
Unlike most Android malware that must trick users into downloading an APK or granting permissions, Midnight Mimosa is already present in the system partition when the device is sold. Bitdefender recorded thousands of devices in more than 150 countries over roughly two years, with the most detections in Mexico, France, Italy, the United States, Germany, Brazil, and Spain. The true scale may be larger because the figures cover only devices visible to the company's technology.
An Infection That Starts Before the Box Is Opened
Cuộc điều tra bắt đầu khi cơ chế App Anomaly Detection của Bitdefender phát hiện gói com.android.system.lite mang dáng vẻ thành phần Android nhưng liên tục cài và gỡ những ứng dụng không liên quan. Gói này được ký bằng chứng chỉ nền tảng, chạy dưới tài khoản hệ thống, không có biểu tượng và không thể bị gỡ bằng thao tác thông thường.
Cùng lõi mã độc còn xuất hiện dưới nhiều tên có vẻ hợp lệ như com.android.sys.prot, com.android.sys.gmsprot and com.android.sys.bcprot. Việc đổi tên, bản dựng và chứng chỉ ký cho thấy tên gói riêng lẻ không phải chỉ dấu đủ tin cậy; hành vi chung và chuỗi hạ tầng mới là yếu tố liên kết các mẫu.

System Privileges Enable Remote Code Loading
Thành phần cài sẵn có quyền cài, xóa ứng dụng, cấp quyền thời gian chạy và thay đổi thiết lập bảo mật mà không cần tương tác. Logic nguy hiểm được giấu trong thư viện native libeasy.so; khi hoạt động, thư viện giải mã một framework Java rồi lấy cấu hình từ máy chủ điều khiển để tải các plugin DEX ở giai đoạn tiếp theo.
Bitdefender identified at least 32 apps disguised as weather tools, app lockers, file managers, OCR utilities, audio editors, or icon customizers. Payloads are installed and removed in rotation, shortening their visibility in the app list, changing file fingerprints, and switching monetization modules while the persistent system component remains in place.
Disabling the Play Store to Evade Inspection
Ngay trước khi cài payload, mã độc tạm vô hiệu hóa gói Google Play Store com.android.vending, được cho là nhằm tránh Play Protect quan sát quá trình cài đặt. Sau đó Play Store được bật lại; một cơ chế dự phòng cũng khôi phục ứng dụng khi người dùng đang thao tác để hạn chế gây nghi ngờ.
Some variants also alter installer records to make malicious apps look as though they came from Google Play. Researchers separately found 13 Google Play apps using the same ad-fraud code and communicating with Midnight Mimosa infrastructure. These store apps lack the firmware package's privileges but can still display ads outside their own interfaces.
From Ad Fraud to Residential Proxies
The main monetization model uses cover apps to load legitimate ads in invisible windows or automatically generate impressions and clicks. This shifts data, power, and device-wear costs to buyers while distorting the advertising ecosystem.
A payload disguised as an app locker also includes a TCP proxy. After registering a device with a remote server, it can receive instructions to connect to a specified destination and relay traffic through the victim's IP address. Bitdefender confirmed that the control infrastructure still accepted registrations but observed no relay targets during testing, so it could not confirm specific attack traffic passing through test devices.
Residential proxies are valuable to cybercriminals because traffic comes from real consumer connections, is difficult to distinguish from normal activity, and can support fraud, target scanning, or source concealment. The report also notes that Accessibility, Notification Access, and SMS permissions are available for remote activation, although researchers did not observe them being used in this campaign.
Unanswered Questions in the Supply Chain
Samples appeared on multiple low-cost devices, including model names associated with the Doogee S200 X and Cubot KINGKONG X, as well as phones impersonating Samsung or Apple products. Some XDA forum users reported suspicious apps reinstalling themselves after removal; in one case, newer official firmware brought the malware back while restoring an older version made it disappear.
Some firmware was signed with certificates bearing the Shenzhen Zediel name, but Bitdefender stresses that this does not prove the entity participated in or knew about the malware installation. Tampering could have occurred at the device designer, firmware integrator, logistics partner, or another link. Public evidence is not sufficient to assign responsibility to a specific company.
What Should Users and Organizations Do?
- Ưu tiên thiết bị có cam kết cập nhật rõ ràng: giá mua thấp không bù được rủi ro khi firmware không minh bạch hoặc nhà sản xuất thiếu kênh hỗ trợ bảo mật.
- Kiểm tra dấu hiệu bất thường: lưu lượng nền, pin hao nhanh, quảng cáo ngoài ứng dụng, Play Store bị tắt hoặc ứng dụng lạ tự xuất hiện là các tín hiệu cần điều tra.
- Cập nhật từ nguồn chính thức đã được xác minh: với model được nhà sản xuất xác nhận có bản vá, sao lưu dữ liệu rồi cài firmware sạch. Khôi phục cài đặt gốc có thể không hiệu quả nếu mã độc nằm trong phân vùng hệ thống.
- Cách ly thiết bị nghi nhiễm: không dùng cho ngân hàng, MFA, email doanh nghiệp hoặc truy cập mạng nội bộ; đổi thông tin đăng nhập từ một thiết bị tin cậy.
- Quản trị thiết bị doanh nghiệp: dùng MDM để chặn model không được phê duyệt, theo dõi gói hệ thống và phát hiện kết nối C2 hoặc proxy bất thường.
Technical users may reduce risk by disabling malicious packages through ADB, but this is not a universal remedy and may destabilize the device. A reliable fix requires cleaned firmware, and devices without patches should no longer be used for sensitive activity.
Lessons from the Midnight Mimosa Profile
Midnight Mimosa shows that the mobile trust model can fail at the factory: platform signatures and system privileges intended to protect the OS become an operator's advantage when firmware is compromised. Installation-time app scanning is not enough; continuous behavior monitoring and firmware provenance must become part of supply-chain controls.
In the budget-device market, transparency about firmware integrators, signing certificates, update schedules, and vulnerability disclosure channels matters as much as hardware specifications. Buyers and organizations should treat phones with unclear supply chains as untrusted devices, especially when they serve as authentication factors or gateways to work data.
VNCyberS compiled from Bitdefender and BleepingComputer















